Enterprise Architecture and Network Design
Enterprise Architecture and Network Design
Enterprise Architecture
ENCOR (350-401) Topics RID: [Link]
R1
Gig 0/1
.1
[Link] /24
.2
•Enterprise Architecture Gig 0/1
AS 65001
RID: [Link]
R2
•Virtualization Technologies Gig 0/2
.2
[Link] /24
•Infrastructure Technologies
.1 Lo1:
Gig 0/1 [Link]/64
RID: [Link]
R3
•Network Management
.5
0/ 1
Gig
.
2
20
0/
00
Gig
3
:2::
19
30
1/6
8.5
.0 /
100
•Network Security
1.1
00
ps
00
Mb [Link]
1.1
Mb
.4 / Gig 0
ps
8.5
20
10
30
0
19
•Network Automation
/1
2/6
0
AS 65002
.6
.2
Gig
AS 65004
/1
RID: [Link] RID: [Link]
ISP1 ISP2
•Exam Preparation
Gi
.1 g 0/ 0 /2
g .6
2 Gi
20 Gi 2 30
[Link]/64
Lo1:
3.0 RID: [Link] /
g0
/1 g 0/ .4
.11 Gi 13
3.0 .2 .5 .1
/3 3.0
0 INET 20
AS 65003
Your Instructor
• Kevin Wallace
• Written a bunch of books & made a ton of video courses for Cisco Press
Collapsed Core
Core Layer
Layer
Distribution
Collapsed
Three-Tier
CoreArchitecture
Architecture
Layer A two-tier
A network
topology
topology
wheredivided
the Core
into and
the Access,
Distribution
Layers
Distribution,
have been
and consolidated.
Core layers.
Access Layer
Spine-Leaf Design for Data Centers
Logically, One Switch
Spine Switches
Leaf Switches
Nodes
On-Premise vs. Cloud Designs
Internet
VPN
Private WAN
MPLS
Metro Ethernet
Considerations
• With a Cloud deployment, there’s no need to maintain local redundant power or hardware.
• With a Cloud deployment, you pay for resource usage instead of purchasing physical hardware.
• Many deployments, called Hybrid deployments, combine both On-Premise and Cloud deployments.
Fabric Capacity Planning
Higher Costs
• Redundant Components
• UPS/Generator
• FHRP
Redundant Design
Types of Backups
• Full: Backs up all data.
• Power
• HVAC
• Floor Space
• Power
• HVAC • Power
• Floor Space • HVAC
• Server Hardware • Floor Space
• Synchronized Data • Server Hardware
IP: [Link]
DG: [Link]
PC 1
Virtual Router Redundancy Protocol (VRRP)
Internet
[Link]
Advertisement Interval (1 second)
Virtual Router
R1 Gig 0 4 R2
/1: 10 / 2
Master .1.1.1 0 . 1 .1.2 Backup
Master
/24 / 1: 1
Gig 0
SW1
IP: [Link]
DG: [Link]
PC 1
Gateway Load Balancing Protocol (GLBP)
The MAC address of The MAC address of
[Link] is [Link] is
1111.1111.1111. 2222.2222.2222.
Internet
AVG
R1 R2
• Round-Robin
AVF Virtual IP: [Link] AVF
MAC: 1111.1111.1111 MAC: 2222.2222.2222
Host-Dependent
•
• Weighted ARP
ARP SW1 What is the MAC address
What is the MAC address of [Link]?
of [Link]?
PC1 Active
ActiveVirtual
VirtualForwarder
Gateway (AVG)
(AVF) PC2
Responds to ARP queries
Forwardsasking
trafficforoffthe
of MAC
the local
address
subnet.
of a default gateway.
Default Gateway: [Link] Default Gateway: [Link]
Stateful Switchover (SSO)
RP1 Neigh
borsh
ip
R1 ip
R2
o r s h
eig h b
N
RP2
The Main Issue: Failing over to a backup route processor might cause
routing protocol neighborships to reset.
Stateful Switchover (SSO)
RP1 Neigh
borsh
ip
R1 ip
R2
o r s h
eig h b
N
RP2
SSO: Sync (Config and State Information)
The Secondary Issue: Packets might be dropped until the forwarding
table is rebuilt.
Stateful Switchover (SSO)
RP1
CEF Neigh
borsh
ip
R1 ip
R2
o r s h
eig h b
N
RP2
SSO: Sync (Config and State Information)
AP 1 AP 2 AP 3
Wireless Deployment Options
VLAN 100 VLAN 100
WLC1 WLC2
CAPWAP Tunnels
Network:
AP1 [Link]/24 AP2
[Link] [Link]
Wireless Deployment Options
VLAN 100 VLAN 200
WLC1 CAPWAP WLC2
Anchor Foreign
Controller Controller
CAPWAP Tunnels
[Link] [Link]
Wireless Deployment Options
Cisco FlexConnect:
• Configure and control remote wireless network
• Similar to Layer 3 roaming with CAPWAP
Central Switched:
• Normal CAPWAP mode of operation
• Typically not the recommended mode
Local Switched:
• Map user traffic to VLAN on adjacent switch
• Control and management traffic still sent over CAPWAP to WLC
Location Services
Location Services
-45 dBm
-75 dBm
Location Services
Cisco Solutions:
• Real-Time Location Services (RTLS)
• Cisco DNA Spaces
• Cisco Meraki platform
Software-Defined WAN
(SD-WAN)
Overview of SD-WAN Technology
Overview of SD-WAN Technology
Enterprise WAN:
• Dedicated circuits traditionally used
• Provide reliability and security
• Rise in cloud usage requires simplicity
Overview of SD-WAN Technology
Inspection and
Security Services
Inspection and
Security Services
MPLS Circuit
SD-WAN
Controller
Cisco SD-WAN:
• Data plane
• Control plane
• Management plane
• Orchestration plane
SD-WAN Implementation
vManage: User interface Management &
Orchestration
vBond: Orchestration and provisioning Plane
Data
Cisco vEdge: Edge routers
Plane
SD-WAN Implementation
Cloud Physical
Data Data
Center Center
LTE
MPLS
Main Satellite
Campus
BR2
Secure provisioning
and configuration
BR1
SD-WAN Implementation
Cloud Physical
Data Data
Center Center
Main Satellite
Campus Edge Router Software Platforms:
BR2
• CSR 1000v Router
• vEdge Cloud Router running Viptela OS
BR1
[Link]/go/sdwandemos
Software-Defined
Access (SD-Access)
Overview of SD-Access Technology
SD-Access Advantages:
• Next-generation policy enforcement
• Security Group Access Control Lists (SGACLs)
• Policies are based on identity rather than addresses
Overview of SD-Access Technology
SD-Access Advantages:
• Secure network segmentation
• Virtualization of physical network
• Separate virtual networks can have separate policies
Overview of SD-Access Technology
Campus Fabric
Overview of SD-Access Technology
Campus Fabric
Overview of SD-Access Technology
Overlay Network
Underlay Network
Overview of SD-Access Technology
SD-Access Fabric
PHYSICAL
On-site Server Room
SD-Access Fabric
Fabric Edge Nodes
SD-Access Fabric
Fabric Edge Nodes
Traditional Wireless:
CAPWAP Tunnel between SD-Access Fabric
AP and WLC for all traffic
On-site Server Room
SD-Access Wireless:
CAPWAP Tunnel between SD-Access Fabric
AP and WLC only for
management traffic
VXLAN Tunnel:
Data from AP to network
On-site Server Room
SD-Access Fabric
Quality of Service (QoS)
Do You Need QoS?
Gig Fast E IP WAN
SW1 R1
Speed Mismatch
Server 1 Gig
Gig Gig
Server 2 Gig SW2
Periodic
Congestion
3 Categories of QoS
Less Strict
DiffServ
Strict
IntServ
Common QoS Mechanisms
• Classification and
Marking
• Queuing
• Congestion Avoidance
• Policing and Shaping
• Link Efficiency
Common QoS Mechanisms
Best
VoIP
VoIP Effort
• Classification and
Marking
• Queuing
• Congestion Avoidance
• Policing and Shaping
• Link Efficiency
Common QoS Mechanisms
• Classification and
Marking
• Queuing
• Congestion Avoidance
• Policing and Shaping
• Link Efficiency
Common QoS Mechanisms
• Classification and
Marking
• Queuing
• Congestion Avoidance
• Policing and Shaping
• Link Efficiency
Common QoS Mechanisms
• Classification and
Marking
• Queuing
• Congestion Avoidance
• Policing and Shaping
• Link Efficiency
Wi-Fi Multimedia (WMM)
Tag Control
Information Bytes
CoS Bits
Type of Service (ToS) Byte
Traffic Class Byte in IPv6
IPv4 or IPv6 Packet
ToS Byte
1 2 3 4 5 6 7 8
IP Precedence
DSCP
RED Drop Ranges
RED Profiles
Probability of Full Dropping
Discard
100 %
Drop Drop Drop
Profile Profile Profile
for for for
AF13, AF12, AF11,
AF23, AF22, AF21,
AF33, & AF32, & AF31, &
25 % AF43 AF42 AF41
Average
25 30 35 100 Queue
Depth
CIR = Bc / Tc
CIR (Committed Information Rate) = AVERAGE speed over the period of a second
Bc (Committed Burst) = Number of bits (for shaping) or bytes (for policing) that are deposited in the token bucket
during a timing interval
128 kbps
Tc (Timing Interval) = The interval at which tokens are deposited in the token bucket
Line Speed
Tc 1 Tc 2 Tc 3 Tc 4 Tc 5 Tc 6 Tc 7 Tc 8
Timing Intervals
Switching Mechanisms
Process Switching
Process Switching
Process Switching:
• Oldest method for Cisco IOS switching
• Every packet is inspected by CPU
Process Switching
Process Switching
Process Switching:
• Processor is directly involved with every packet
• Not ideal in modern networks
• Available on every Cisco router platform
• Debugging uses process switching
Cisco Express Forwarding (CEF)
Cisco Express Forwarding (CEF)
CEF Benefits:
• Less CPU-intensive than older switching methods
• Distributed CEF (dCEF) allows line card forwarding
• CEF Forwarding Information Base (FIB)
• CEF Adjacency Table
Cisco Express Forwarding (CEF)
Forwarding
Information
Base
Cisco Express Forwarding (CEF)
Adjacency
Table
SW1
[Link] /24
Gig 0/1 .1
R1
Gig 0/2 .1
CEF Demo [Link] /24
Gig 0/1 .2
R2
Gig 0/2 .1
[Link] /24
SW2
CAM vs. TCAM
CAM vs. TCAM
SW1
Fa
1/
Fa 1/0/13
0/
14
Fa 0/3
Fa
0/
3
Fa 0/1 Fa 0/1
Fa 0/2 Fa 0/2
SW2 SW3
MAC Address MAC Address
[Link].ea00 0014.69ac.2000
FIB vs. RIB
FIB vs. RIB
BEST PATH